ai

9 posts.

  • The Evolution of Penetration Testing

    I used to spend most of my time testing web applications. My first look at AI pentesting products suggests the market is moving from point-in-time reports toward continuous, context-rich security testing.

  • MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue Injection

    A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.

  • The MCP confused deputy problem

    A hands-on MCP lab showed how a valid tenant key can still retrieve another tenant's project when the server never checks resource ownership.

  • MCP security labs: path bypasses and poisoned tool responses

    Two MCP labs showed different failures at the same boundary: a filesystem server trusted a string prefix, while a facts server poisoned the agent's next tool call.

  • MCP security: when prompt injection gets a tool

    MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.

  • Poisoning an AI assistant's memory

    Lakera's MindfulChat challenge made persistent memory feel like a real application attack surface, not just a model prompt.

  • An interactive playground for LLM security testing

    I worked through an interactive OWASP LLM Top 10 playground and found a useful starting map, a few strong concepts, and several labs that needed more explanation.

  • Web LLM attacks, deeper into indirect prompt injection

    Indirect prompt injection and insecure output handling showed me that an LLM can turn ordinary application content into an attack path.

  • Web LLM attacks

    Mapping an LLM's tools first turned two PortSwigger labs into the same repeatable web-testing method.

Ryan Sacatani

Simply curious about the world, constantly building and breaking things for fun.

sacataniryan1@gmail.com ↗

BrowseBrowse topics